# How to add my network logs of my applications to elastic/observability

**URL:** <https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704>\
**Category:** Elastic Agent\
**Tags:** integrations\
**Created:** [March 14, 2023, 9:48pm UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704 "2023-03-14T21:48:28Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![schavaku](https://avatars.discourse-cdn.com/v4/letter/s/aca169/32.png) [@schavaku](https://discuss.elastic.co/u/schavaku)\
**Post date:** [March 14, 2023, 9:48pm UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704/1 "2023-03-14T21:48:28Z")

</div>

I would like to access my logs and create a dashboard in Elasticsearch/observability. Please let me know how to integrate the application logs from the network. I would like to know the steps.

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [March 23, 2023, 6:17pm UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704/2 "2023-03-23T18:17:03Z")

</div>

Hi @schavaku,  
Without any specifics on the types of logs and dashboards you want all I can give you is a general answer.

1. [Install logstash](https://www.elastic.co/guide/en/logstash/current/installing-logstash.html)
2. [Configure logstash](https://www.elastic.co/guide/en/logstash/current/setup-logstash.html) to process your log files and send them to elastic.
3. Create visualizations for your dashboard in kibana using [Lens](https://www.elastic.co/guide/en/kibana/current/lens.html) and then save them to a new dashboard.

---

<div class="post-metadata">

**Author:** ![schavaku](https://avatars.discourse-cdn.com/v4/letter/s/aca169/32.png) [@schavaku](https://discuss.elastic.co/u/schavaku)\
**Post date:** [March 23, 2023, 8:09pm UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704/3 "2023-03-23T20:09:41Z")

</div>

Thank you so much. I am using Filebeat instead of logstash to get the logs. I was able to get them and is able to create a dashboard. I am able to get the log file as a whole but I am not sure if I can further read the log file fields so that I can create a dashboard in a meaningful way.

The other question I have is what is the difference between Filebeat and Logstash and in what circumstances we use one over another

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [March 23, 2023, 8:32pm UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704/4 "2023-03-23T20:32:38Z")

</div>

> [@schavaku](#):
>
> I am able to get the log file as a whole but I am not sure if I can further read the log file fields so that I can create a dashboard in a meaningful way.

You might want to try using the [filebeat processor dissect](https://www.elastic.co/guide/en/beats/filebeat/current/dissect.html) to further break out your file into meaningful fields.

> [@schavaku](#):
>
> The other question I have is what is the difference between Filebeat and Logstash and in what circumstances we use one over another

Filebeat is great for processing files, especially if the files are some of the supported [modules](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules.html).

Logstash is the original data manipulation/ingestion/transform program used by the ELK stack (the L in this case). Think of it like a swiss-army knife. It can pretty much do it all, but can be more complicated to use. Really depends on the use case though.

---

<div class="post-metadata">

**Author:** ![schavaku](https://avatars.discourse-cdn.com/v4/letter/s/aca169/32.png) [@schavaku](https://discuss.elastic.co/u/schavaku)\
**Post date:** [March 23, 2023, 9:50pm UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704/5 "2023-03-23T21:50:23Z")

</div>

Thank you.

My file pattern looks like this

\server\h\*\*\ ***_\*_\*** _ **\*** \Log\file1  
\server\h\*\*\*__\*\*_\*\ ***\*** \Log\file2

each file has some codes and failures and success etc

I will use the dissect as you suggest but I am wondering if I can use the dissect settings in file beat yml directly

Also, I have one more question:

Can I fire an email based on a code that I see in my log file? If so where can I setup the rules for filebeat?

Thanks for answering my questions

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [March 24, 2023, 2:11am UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704/6 "2023-03-24T02:11:47Z")

</div>

> [@schavaku](#):
>
> can use the dissect settings in file beat yml directly

Yes I think you can just add a processor section as needed ([for example](https://www.elastic.co/guide/en/beats/filebeat/current/dissect.html#dissect-example)).

> [@schavaku](#):
>
> Can I fire an email based on a code that I see in my log file? If so where can I setup the rules for filebeat?

I don't think filebeat can but Logstash can. Basically anything filebeat can do so can logstash and then some. Logstash has an [output plugin](https://www.elastic.co/guide/en/logstash/8.6/output-plugins.html) that can [send email](https://www.elastic.co/guide/en/logstash/8.6/plugins-outputs-email.html).  
Really briefly logstash has three main configuration parts: inputs-\>filters-\>outputs. Filters are optional.  
Good luck!

---

<div class="post-metadata">

**Author:** ![schavaku](https://avatars.discourse-cdn.com/v4/letter/s/aca169/32.png) [@schavaku](https://discuss.elastic.co/u/schavaku)\
**Post date:** [March 28, 2023, 9:45pm UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704/7 "2023-03-28T21:45:46Z")

</div>

Thank you.

I have a folder with all the log files coming everyday.

I want to dissect the latest file

I used the following dissect  
processors:

- dissect:  
tokenizer: '%{log-level} | %{date-time} | %{exit-code} | %{server-hostname} | %{log-path}

but I am getting a parsing error

dissect\_parsing\_error

Pls let me know that what goes wrong from my side. Thank you

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [March 29, 2023, 1:34pm UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704/8 "2023-03-29T13:34:30Z")

</div>

Sure, can you provide a few lines of the file in question to see what's going on. Please remember to redact any sensitive or confidential information.

---

<div class="post-metadata">

**Author:** ![schavaku](https://avatars.discourse-cdn.com/v4/letter/s/aca169/32.png) [@schavaku](https://discuss.elastic.co/u/schavaku)\
**Post date:** [March 29, 2023, 4:30pm UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704/9 "2023-03-29T16:30:09Z")

</div>

INFO | 03/29/2023\_05:19:39 | Exit Code: 0 | | BatchJob.Run  
INFO | 03/29/2023\_05:19:39 | \*\*\*\*\*\*\*\*\*\* complete. | | JobEngine.Common.Client.LogToFile  
INFO | 03/29/2023\_05:19:39 | \*\*\*\*\*\*\*\*\*\*|Run complete. | | Batch.JobEngine.Common.ApiClient.LogToFile  
INFO | 03/29/2023\_05:19:39 | \*\*\*\*\*\*\*\*\*\*| \*\*\*\*\* Job Results \*\*\*\*\* | Schedule ID:3657 | Exited with Exit Code: 0. Exit Message: . Update Last Run Date: False. Last Run Date: 3/29/2023 5:19:39 AM | | Batch.JobEngine.Common.Client.LogToFile  
INFO | 03/29/2023\_05:19:39 | \*\*\*\*\*\*\*\*\*\*|Skipping LastRunDate update as the BatchJobResult.UpdateLastRunDate was set to 'false' and/or an error occurred for ScheduleId: 3657. UpdateLastRunDate: False, Error Occurred: False | | Batch.JobEngine.Common.ApiClient.LogToFile

Not sure, the issue could be there are 6 pipes for some data and 5 pipes for some other data. Thanks for looking into this.

---

<div class="post-metadata">

**Author:** ![schavaku](https://avatars.discourse-cdn.com/v4/letter/s/aca169/32.png) [@schavaku](https://discuss.elastic.co/u/schavaku)\
**Post date:** [March 29, 2023, 6:11pm UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704/10 "2023-03-29T18:11:08Z")

</div>

I was able to parse it. Thank you

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [March 30, 2023, 2:47pm UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704/11 "2023-03-30T14:47:59Z")

</div>

Oh nice, I was just going to take a swing at it. Do you have anything to share in case someone else runs into a similar issue? Not required of course, but it could be your first solution. 🙂

---

<div class="post-metadata">

**Author:** ![schavaku](https://avatars.discourse-cdn.com/v4/letter/s/aca169/32.png) [@schavaku](https://discuss.elastic.co/u/schavaku)\
**Post date:** [March 30, 2023, 10:12pm UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704/12 "2023-03-30T22:12:52Z")

</div>

I used the following and it worked. Thank you.

```
  tokenizer: '"%{log-level} | %{date-time} | %{exit-code} | %{server-hostname} | %{log-path}"'
  field: "message"
  target_prefix: ""

```

I have the following question now.

How can I create a dashboard using the message of this log file?. This message consists 5 fields. But I would like to get one or two of these fields and show them in the dashboard.

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [April 2, 2023, 2:12am UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704/13 "2023-04-02T02:12:34Z")

</div>

Sure thing. Creating a new dashboard is pretty easy and this [documentation](https://www.elastic.co/guide/en/kibana/current/create-a-dashboard-of-panels-with-web-server-data.html) should help you get started.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 30, 2023, 2:12am UTC](https://discuss.elastic.co/t/how-to-add-my-network-logs-of-my-applications-to-elastic-observability/327704/14 "2023-04-30T02:12:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
